Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
96 articles found · #nis-2
Liechtenstein: UBO register hacked (31,000 individuals affected)
Liechtenstein confirms data exfiltration from its UBO register (VwbP), affecting around 31,000 individuals. A stark reminder: these registers hold highly sensitive data that must be protected as critical assets.
South Staffordshire Water: £963k fine for detection failures
The ICO fined South Staffordshire Water £963,900 for ~5% monitoring coverage and near-absent detection. Here’s why a 24/7 operated EDR/XDR stack is now essential.
CSSF 25/903: Support PSF — the inventory/CMDB as key evidence
CSSF 25/903 strengthens 24/850 and requires structured evidence on support PSF ICT organization. An automated inventory/CMDB becomes central to trace assets, dependencies and controls, and to meet NIS 2 obligations.
Ernst & Young: support ticket data leak — DLP for GDPR Art. 32 and cross‑border transfers
In July 2026, EY confirmed fraudulent access to a third‑party ticketing tool with tax documents downloaded. Here is a practical DLP to curb exfiltration and evidence GDPR compliance (Art. 32 and 44‑49).
LAUNDRY BEAR/NCSC: 'beehive' targets Zimbra — messaging security (NIS 2)
NCSC and partners expose “LAUNDRY BEAR”: a zero‑click campaign against Zimbra. This is the email stack (SEG + DMARC/SPF/DKIM) and NIS 2 actions to reduce risk and notify properly.
Coca‑Cola/Fairlife: ransomware, production halt and data theft
Coca‑Cola confirms data theft following a ransomware attack against Fairlife. U.S. production was suspended mid‑July; the Anubis group claims up to 1 TB of data.
CSSF 26/906: strengthened governance and risk — an ISO 27001 ISMS to evidence NIS 2
CSSF 26/906 tightens governance and risk for payment/e-money institutions, with compliance due by 30 June 2026. A certified ISO 27001 ISMS operationalizes these requirements and NIS 2 Article 21.
Secureholiday (Ctoutvert): 41,577 Dutch campers affected
Ctoutvert (Secureholiday) confirms a breach affecting 41,577 Dutch campers. No IBANs or cards leaked, but emails, phone numbers and stay dates exposed and used for targeted fraud.
Six weeks of downtime: German SME goes insolvent after cyberattack
On 14 July 2026, ZEGO (Aschaffenburg, DE) filed for insolvency after a March 29 cyberattack halted production for nearly six weeks—an explicit illustration of the operational cost of incidents for manufacturers.
CSSF 26/914: AMLA supervision — the ICT inventory becomes vital
CSSF 26/914 identifies entities eligible for AMLA’s direct supervision. Governance and traceability tighten: a reliable, continuous inventory/CMDB is now essential to evidence NIS 2/ISO 27001 controls.
NIS 2 and supply chain: the EU Toolbox is a game changer
Adopted on 13/02/2026, the EU ICT Supply Chain Security Toolbox is now the operational benchmark for NIS 2 Article 21(2)(d). In Luxembourg, the ILR will verify its implementation by entities.
ILR — CP/N26/2 consultation and NIS 2 24-hour notification
ILR opens consultation on national NIS 2 incident notification (CP/N26/2). Here are the rules, the 24/72/30 timeline, and the SIEM/SOC stack to report within 24 hours reliably.